Legal
Privacy Policy
Bell AI Ltd · Company No. 15249179 · 128 City Road, London EC1V 2NX, United Kingdom
Effective date: 19 May 2026 · Version 1.0 · Contact: success@getbell.ai
This Privacy Policy explains how Bell AI Ltd ("Bell AI", "we", "us") collects, uses, shares and protects personal data when you use the Bell AI email client, our AI assistant Bella, our websites, and related services (together, the "Service"). It also sets out your rights and how to exercise them.
In plain terms: we process your email so Bella can work for you. We never sell your data, we never use your email content for advertising, and we never use your email content — or any data obtained from Google or Microsoft — to train generalised artificial intelligence or machine-learning models, whether ours or anyone else's. This is the default and the only setting.
1. Who we are
Bell AI Ltd is a company incorporated in England and Wales (company number 15249179) with its registered office at 128 City Road, London, EC1V 2NX, United Kingdom. We are registered with the UK Information Commissioner's Office ("ICO"). For privacy enquiries, contact privacy@getbell.ai.
2. Our role: controller or processor
How this policy applies depends on how you use the Service:
- Individual users. Where you sign up for the Service in a personal capacity, Bell AI is the controller of your personal data and this policy applies in full.
- Business customers. Where you use the Service under an account provisioned by your employer or another organisation, that organisation is the controller of Service Content and Bell AI acts as its processor under our Data Processing Agreement. The organisation's own privacy notice governs that processing; this policy applies to data for which we remain controller (such as account, billing and security data).
3. Information we collect
| Category | What it includes | Source |
|---|---|---|
| Account Data | Name, email address, password hash or OAuth identifiers, profile photo, workspace settings, plan and subscription status | You; your identity provider (Google or Microsoft) |
| Service Content | The content of emails, attachments, calendar entries, contacts, drafts, labels and tasks that you connect to or create in the Service, and your instructions to Bella | Your connected mailbox; you |
| Personalisation Data | Preferences, writing-style signals, triage rules and behavioural patterns Bella learns to act on your behalf, derived solely from your own account | Generated by the Service |
| Usage Data | Feature interactions, in-app events, error logs, diagnostic data | Generated by the Service |
| Device Data | IP address, browser type, operating system, device identifiers, approximate location derived from IP | Your device |
| Payment Data | Billing name, address, VAT number, transaction history. Card details are collected and held by our payment processor; we never store full card numbers | You; payment processor |
| Support Data | Communications you send us, including support tickets and feedback | You |
4. How we use information and our legal bases
Under the UK GDPR we must have a legal basis for each use of personal data:
| Purpose | Data used | Legal basis (UK GDPR Art. 6) |
|---|---|---|
| Provide the Service: read, triage, draft, send and follow up on email through Bella; the Solve page; collaboration features | Account Data; Service Content; Personalisation Data | Performance of a contract (Art. 6(1)(b)) |
| Personalise Bella to your behaviour within your own account | Service Content; Personalisation Data | Performance of a contract (Art. 6(1)(b)) |
| Operate, secure and debug the Service; prevent fraud and abuse | Usage Data; Device Data; Account Data | Legitimate interests (Art. 6(1)(f)) — keeping the Service secure and reliable |
| Billing and account administration | Account Data; Payment Data | Performance of a contract (Art. 6(1)(b)); legal obligation (Art. 6(1)(c)) for tax and accounting records |
| Service communications (security notices, changes to terms, transactional email) | Account Data | Performance of a contract (Art. 6(1)(b)); legal obligation (Art. 6(1)(c)) |
| Marketing communications about Bell AI products | Account Data (never Service Content) | Consent (Art. 6(1)(a)) or legitimate interests for existing customers under PECR soft opt-in; opt out at any time |
| Product analytics and improvement | Usage Data (aggregated or pseudonymised; never Service Content) | Legitimate interests (Art. 6(1)(f)) — understanding how the Service is used |
| Compliance with law, legal claims, regulatory requests | Any category, as strictly necessary | Legal obligation (Art. 6(1)(c)); legitimate interests (Art. 6(1)(f)) |
What we never do. We never sell personal data. We never use Service Content for advertising, behavioural profiling for marketing, or credit decisions. We never use Service Content to train generalised AI or machine-learning models. Automated processing by Bella is carried out to perform our contract with you; actions with legal or similarly significant effects are not taken without human involvement available on request (Art. 22 UK GDPR).
5. Google user data
If you connect a Google account, the Service accesses Google user data through Google APIs, including restricted Gmail scopes. This section explains exactly what we access, why, and the limits we operate under.
5.1 Scopes we request and why
| Google scope | What it allows | Why Bell AI needs it |
|---|---|---|
| gmail.readonly | Read email messages, threads, labels and settings | So Bella can read and triage your inbox, surface priorities, and prepare the Solve page |
| gmail.modify | Apply and remove labels, archive, mark read/unread, move messages | So Bella can organise your inbox on your instructions and learned preferences |
| gmail.send | Send email from your address | So Bella can send drafts and follow-ups you have delegated to her |
| gmail.compose | Create and update drafts | So Bella can prepare drafts for your review and co-drafting |
| userinfo.email / userinfo.profile / openid | Your email address, name and profile photo | Account creation, sign-in and identifying your connected mailbox |
| calendar | Read and create calendar events | So Bella can schedule and respond to meeting requests in email |
| contacts.readonly | Read contacts | So Bella can recognise correspondents and address email correctly |
We request the minimum scopes necessary for these features. If you decline a scope, the corresponding feature is unavailable, but you may still use the rest of the Service where technically possible.
5.2 Limited Use disclosure
Bell AI's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
In accordance with the Limited Use requirements:
- We only use Google user data to provide and improve the user-facing features of the Service that are prominent in its interface — reading, triaging, drafting, organising, sending and following up on your email, and the related personalisation described in this policy.
- We do not transfer Google user data to third parties except: (a) to provide or improve those user-facing features, using sub-processors bound by this policy and the safeguards in section 8; (b) for security purposes, such as investigating abuse; (c) to comply with applicable law; or (d) as part of a merger, acquisition or sale of assets, after providing you with prominent prior notice.
- We do not use Google user data for advertising, including retargeting, personalised or interest-based advertising, and we do not allow any third party to do so.
- We do not allow humans to read your Google user data, except: (a) with your affirmative agreement for specific messages (for example, where you ask our support team to investigate an issue in a specific thread); (b) where necessary for security purposes, such as investigating abuse; (c) to comply with applicable law; or (d) where the data has been aggregated and anonymised and is used only for internal operations.
- We do not use Google user data — including Gmail content — to develop, improve or train generalised artificial intelligence or machine-learning models. Google user data is processed by AI models solely to deliver the user-facing features above, on a per-request basis, and our AI sub-processors are contractually prohibited from retaining it or training on it (see section 6).
5.3 Retention and revocation of Google user data
You can disconnect your Google account at any time in the Service settings or by revoking Bell AI's access at myaccount.google.com/permissions. On disconnection or account deletion, we delete Google user data from our systems within 30 days, except where retention is required by law, and we instruct sub-processors to do the same. Cached or backup copies are purged within our standard backup cycle of 35 days.
6. AI processing and our no-training commitment
Bella is powered by third-party large language models. When Bella performs a task, the relevant Service Content is transmitted to an AI sub-processor solely to generate the output you requested. Our AI sub-processors are bound by contractual terms under which they:
- may not use your data to train, improve or develop their models or any other models;
- operate under zero or minimal retention, deleting inputs and outputs promptly after processing; and
- may not use your data for any purpose other than returning the requested output to Bell AI.
Current AI sub-processors include Anthropic (Claude) and Google (Gemini). Personalisation Data is derived and applied only within your own account; it is never pooled across customers and never used to build models that serve other users.
7. Microsoft user data
If you connect a Microsoft account (Outlook.com or Microsoft 365), the Service accesses Microsoft user data through the Microsoft Graph API. This section explains exactly what we access, why, and the limits we operate under. Our access to and use of data obtained through Microsoft APIs complies with the Microsoft APIs Terms of Use and the Microsoft identity platform policies.
7.1 Scopes we request and why
| Microsoft Graph scope | What it allows | Why Bell AI needs it |
|---|---|---|
| Mail.Read | Read email messages, folders and settings | So Bella can read and triage your inbox, surface priorities, and prepare the Solve page |
| Mail.ReadWrite | Apply and remove categories, move messages, mark read/unread, archive | So Bella can organise your inbox on your instructions and learned preferences |
| Mail.Send | Send email from your address | So Bella can send drafts and follow-ups you have delegated to her |
| Mail.ReadWrite (drafts) | Create and update drafts | So Bella can prepare drafts for your review and co-drafting |
| User.Read / email / profile / openid | Your email address, name and profile photo | Account creation, sign-in and identifying your connected mailbox |
| Calendars.ReadWrite | Read and create calendar events | So Bella can schedule and respond to meeting requests in email |
| Contacts.Read | Read contacts | So Bella can recognise correspondents and address email correctly |
| offline_access | Maintain access via refresh tokens | So Bella can continue working on your behalf without asking you to sign in repeatedly |
We request the minimum scopes necessary for these features. If you decline a scope, the corresponding feature is unavailable, but you may still use the rest of the Service where technically possible.
7.2 Limited use of Microsoft user data
We apply the same limited-use commitments to Microsoft user data as we do to Google user data:
- We only use Microsoft user data to provide and improve the user-facing features of the Service — reading, triaging, drafting, organising, sending and following up on your email, and the related personalisation described in this policy.
- We do not transfer Microsoft user data to third parties except: (a) to provide or improve those user-facing features, using sub-processors bound by this policy and the safeguards in section 8; (b) for security purposes, such as investigating abuse; (c) to comply with applicable law; or (d) as part of a merger, acquisition or sale of assets, after providing you with prominent prior notice.
- We do not use Microsoft user data for advertising, including retargeting, personalised or interest-based advertising, and we do not allow any third party to do so.
- We do not allow humans to read your Microsoft user data, except: (a) with your affirmative agreement for specific messages (for example, where you ask our support team to investigate an issue in a specific thread); (b) where necessary for security purposes, such as investigating abuse; (c) to comply with applicable law; or (d) where the data has been aggregated and anonymised and is used only for internal operations.
- We do not use Microsoft user data — including Outlook content — to develop, improve or train generalised artificial intelligence or machine-learning models. Microsoft user data is processed by AI models solely to deliver the user-facing features above, on a per-request basis, and our AI sub-processors are contractually prohibited from retaining it or training on it (see section 6).
7.3 Retention and revocation of Microsoft user data
You can disconnect your Microsoft account at any time in the Service settings or by revoking Bell AI's access at account.live.com/consent/Manage (personal accounts) or myapps.microsoft.com (work or school accounts). On disconnection or account deletion, we delete Microsoft user data from our systems within 30 days, except where retention is required by law, and we instruct sub-processors to do the same. Cached or backup copies are purged within our standard backup cycle of 35 days.
8. Who we share data with
We share personal data only with:
- Sub-processors who help us run the Service — hosting and infrastructure (e.g. Supabase / AWS / GCP), AI model providers (section 6), payment processing (e.g. Stripe), email delivery, and customer support tooling. Each is bound by a written contract imposing confidentiality, security and data-protection obligations no less protective than this policy, and — for Google user data — the Limited Use requirements. A current sub-processor list is available on request.
- Professional advisers and authorities where required by law, court order, or to establish, exercise or defend legal claims, and where we are legally permitted we will notify you before disclosing Service Content.
- A successor entity in a merger, acquisition, financing or sale of assets, in which case this policy continues to apply to your data and we will give you prominent prior notice of any change of controller or material change of practice, including — for Google user data — the notice required by the Limited Use requirements.
We do not share personal data with advertising networks or data brokers, and we do not permit analytics providers to access Service Content.
9. International transfers
We are UK-based, but some sub-processors process data outside the UK, including in the United States. Where personal data is transferred out of the UK or EEA, we rely on: (a) UK adequacy regulations (including, for the US, the UK Extension to the EU–US Data Privacy Framework where the recipient is certified); (b) the ICO's International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses; or (c) the EU Standard Contractual Clauses for EEA-origin data — in each case with supplementary measures where required. Copies of the relevant safeguards are available on request.
10. How long we keep data
| Category | Retention |
|---|---|
| Service Content (including Google and Microsoft user data) | For as long as your account is active and the mailbox remains connected. Deleted within 30 days of account deletion or disconnection (section 5.3) |
| Personalisation Data | Deleted with your account |
| Account Data | Life of account plus up to 90 days for dispute handling |
| Payment and tax records | 6 years from the end of the relevant financial year (UK legal requirement) |
| Usage and security logs | 12 months, then deleted or anonymised |
| Support Data | 24 months from ticket closure |
| Backups | Rolling cycle of 35 days; deleted data falls out of backups within that cycle |
11. Security
We apply technical and organisational measures appropriate to the risk, including encryption in transit (TLS 1.2+) and at rest (AES-256), OAuth-based mailbox access (we never see or store your mailbox password), role-based access controls, least-privilege production access, logging and monitoring, and vendor security review. No system is perfectly secure; if a personal data breach occurs that is likely to result in a risk to your rights, we will notify the ICO within 72 hours and affected users without undue delay, as required by Articles 33–34 UK GDPR.
12. Your rights
Subject to conditions in the UK GDPR, you have the right to: access your personal data; rectify inaccurate data; erase data; restrict processing; data portability; object to processing based on legitimate interests (including direct marketing, which we will always stop on objection); withdraw consent at any time where consent is the basis; and not be subject to solely automated decisions with legal or similarly significant effects. To exercise any right, contact privacy@getbell.ai. We respond within one month (extendable by two months for complex requests, with notice). We will verify your identity before acting. You also have the right to complain to the ICO (ico.org.uk; +44 303 123 1113) or, if you are in the EEA, to your local supervisory authority — though we would welcome the chance to resolve your concern first.
13. Children
The Service is not directed at children under 18 and we do not knowingly collect their data. If you believe a child has provided us personal data, contact us and we will delete it.
14. Cookies
Our websites use strictly necessary cookies and, with your consent, analytics cookies. We do not use advertising cookies.
15. Changes to this policy
We may update this policy from time to time. For material changes — including any change to how we handle Google user data — we will give you prominent advance notice in the Service or by email, and where required by law we will seek your consent. The "Last updated" date shows the current version; prior versions are available on request.
16. Contact
Bell AI Ltd, 128 City Road, London, EC1V 2NX, United Kingdom — privacy@getbell.ai.
Version 1.0 — Effective 19 May 2026